[OPSAWG] Dnsdir last call review of draft-ietf-opsawg-mud-tls-13

"R. Gieben via Datatracker" <noreply@ietf.org> Mon, 11 March 2024 07:42 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: opsawg@ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 7D56CC14F6BF; Mon, 11 Mar 2024 00:42:47 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: "R. Gieben via Datatracker" <noreply@ietf.org>
To: dnsdir@ietf.org
Cc: draft-ietf-opsawg-mud-tls.all@ietf.org, last-call@ietf.org, opsawg@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.7.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <171014296749.47429.4984681589830963630@ietfa.amsl.com>
Reply-To: "R. Gieben" <miek@miek.nl>
Date: Mon, 11 Mar 2024 00:42:47 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/GzcqqWDt-Xb2dcgMQLkVJYu-PvY>
Subject: [OPSAWG] Dnsdir last call review of draft-ietf-opsawg-mud-tls-13
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.39
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Mar 2024 07:42:47 -0000

Reviewer: R. Gieben
Review result: Ready with Nits

Hi all,

I've reviewed version 13 of draft-ietf-opsawg-mud-tls for dnsdir and found only
few things in the 'nits' category.

1. DoT (dns over tls) is mentioned but there is no reference to RFC 7858, might
be good to add a reference (to the Introduction section)? 2. DoT traffic itself
might be more traceable because it runs on a different port (853) - unsure if
the authors want/need to say more about this?

Paragraph 4.2 "Encrypted DNS" looks correct to me.

Regards,
Miek